Privacy Policy

Effective date: 21 August 2026 · Website: cloudstream.pro · App: CloudStream TV (com.cloudstream.app) · Publisher: CloudStream

CloudStream operates the cloudstream.pro website and the CloudStream TV media-player applications. CloudStream does not host, sell, or distribute TV channels, movies, or series. You supply your own legally obtained playlist credentials (M3U playlist URL or Xtream Codes server details). This policy describes what our website, apps, and related services process, how that information is used, and the choices you have.

1. Who we are

The data controller for CloudStream TV app licensing, activation, and phone-to-TV pairing services is CloudStream, operating at https://cloudstream.pro/. For privacy questions contact support@cloudstream.pro.

2. Information we collect

2.1 Data stored on your device (local only)

Unless you choose to back up or share it, the following stays on your Android device in app storage (Room database, DataStore, or encrypted preferences):

Android backup is enabled (android:allowBackup="true"). When your device backup is on, the app can include your provider database, preferences, and settings in Google’s device backup and device-to-device transfer (see backup_rules.xml). In-place app updates always keep your playlists and settings. Uninstalling the app still removes local data unless you exported a backup file, used Google Drive backup, or restore from a device backup.

2.2 Data sent to CloudStream servers

When you use CloudStream activation, subscription sync, or phone pairing, the app contacts https://cloudstream.pro/customers/ and may transmit:

DataPurposeWhen sent
Android device ID (ANDROID_ID) or registered device IDLicense binding, pairing, playlist proxyActivation, status sync, pairing
MAC address (hardware if available, otherwise a deterministic value derived from device ID)Device identification for admin support and playlist accessActivation, status sync, pairing
Hardware fingerprint (hashed device characteristics: model, board, screen size, SDK)TV Device ID display and admin lookupStatus sync
Device model / device nameSupport and admin dashboardStatus sync, pairing session
Activation codeValidate app license or subscription planWhen you enter a code
Pairing tokenLink your phone browser session to the TVQR / phone pairing flow
Email addressAssociate your CloudStream customer accountReturned by server after successful activation (if applicable)

We do not receive your IPTV stream content. Playlist credentials you add may be submitted to your provider’s servers or, for CloudStream-managed customers, to our customer API solely to retrieve your assigned playlist.

2.3 Data sent to your IPTV provider

To play content, the app connects directly to servers and URLs you configure (Xtream API, M3U, Stalker portal, EPG sources, etc.) and sends credentials required by that provider. CloudStream does not control those third-party services. Review your provider’s privacy policy for their practices.

2.4 Google services and advertising

For advertising, Google and its partners may process information such as the Android Advertising ID when available and permitted, IP address, approximate location derived from network information, device and app information, ad interactions, diagnostics, and consent signals. Google may use this information to provide personalized, non-personalized, or limited ads as permitted by your choices and applicable law. See How Google uses information from sites or apps that use its services and Google’s Privacy Policy.

The app waits for UMP to confirm whether ads may be requested. If Google reports that ads cannot be requested, CloudStream does not initialize or request an ad. Refusing advertising consent does not disable the core media-player functions. Your seven-day trial and activation status are separate from your advertising-consent choice.

2.5 Website use, cookies, and Google AdSense

When you visit cloudstream.pro, our hosting and security providers may process your IP address, browser and device type, requested URL, referring page, timestamps, approximate network location, and security events. This information is used to deliver pages, prevent abuse, investigate errors, and maintain the website. Checkout, account, activation, and pairing pages may also use essential session storage or cookies required to complete the function you request.

If Google AdSense is enabled after the website is approved, Google and participating third-party vendors may use cookies, web beacons, IP addresses, device or browser identifiers, consent signals, and ad interactions to deliver, limit, secure, and measure advertising on eligible public content pages. Depending on your location and choices, ads may be personalized, non-personalized, or limited. Google explains this processing in How Google uses information from sites or apps that use its services and its Advertising technologies notice.

Where required, we use a Google-certified consent management platform for website advertising. Visitors in the European Economic Area, United Kingdom, and Switzerland can accept, reject, or manage eligible advertising purposes before personalized ads are requested. Supported US-state visitors may receive additional privacy choices. You can also review Google advertising controls at My Ad Center. More information is available in our Cookie Policy.

Google ads are not intended for checkout, account-login, device-pairing, error, or other low-content utility screens.

2.6 Optional metadata enrichment

When information supplied by your playlist is missing, the app may send the content type, title, year, and app language to the CloudStream metadata endpoint. Our server forwards that lookup to The Movie Database (TMDB) and returns available artwork and descriptive metadata. Playlist credentials, device identifiers, and viewing history are not included in this lookup. Results may be cached on our server for performance and abuse prevention.

This product uses the TMDB API but is not endorsed or certified by TMDB.

2.7 What we do not collect

3. How we use information

4. Legal bases (EEA/UK/Switzerland users)

We process data based on: (a) performance of a contract — providing the app and your subscription; (b) legitimate interests — fraud prevention, device binding, service security, and non-personal metadata lookup; and (c) consent — optional Google Sign-In/Drive backup, notification permission, and advertising storage, access, or personalization where consent is required. Google and its advertising partners identify their applicable purposes and legal bases in the consent form. You may refuse or withdraw advertising consent without losing the app’s core media-player functions; trial expiry and license activation remain separate.

5. Data retention

6. Sharing and disclosure

We may share data with:

CloudStream does not sell personal data to data brokers. Advertising-related processing and sharing by Google and participating partners occurs only as described above and subject to the privacy choices presented through UMP.

7. Security

Provider passwords are encrypted at rest. Parental PINs are hashed with PBKDF2. Network traffic to CloudStream uses HTTPS. The app allows cleartext HTTP where required by user-supplied IPTV providers (usesCleartextTraffic). You are responsible for using lawful providers and secure credentials.

8. Children’s privacy

CloudStream TV is not directed at children under 13. The app includes optional parental controls, but users may access third-party streams with mature themes depending on their IPTV subscription. Parents and guardians are responsible for provider choice and PIN configuration.

9. International transfers

CloudStream servers may be located outside your country. Where required, we use appropriate safeguards for cross-border transfers.

10. Your rights and choices

11. Google Play distribution

Play Store builds disable sideloaded app updates, third-party plugin APK installation, and offline license bypass codes. Updates are delivered through Google Play. Self-update checks contact cloudstream.pro or GitHub only in non-Play builds. The Google Play mobile build can operate in an ad-supported state during an eligible free or trial entitlement; recognized lifetime activations are ad-free. Google Play Android TV devices do not initialize the mobile advertising SDK.

12. Copyright and user responsibility

CloudStream TV is a player only. It does not bundle copyrighted channels, logos, or media. You must have lawful rights to any playlist or stream you add. CloudStream is not responsible for unauthorized content accessed through user-supplied credentials.

13. Changes to this policy

We may update this policy. Material changes will be posted at this URL with a revised effective date. Continued use after changes constitutes acceptance.

14. Contact

CloudStream
Website: cloudstream.pro
Email: support@cloudstream.pro
WhatsApp support: +44 7537 105407